New User, Welcome!     Login

<< Previous Next >>

Change log

VMSA-2009-0010 VMware Hosted products update libpng and Apache HTTP Server

   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6388
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5000
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0005

- ------------------------------------------------------------------------
6. Change log

2009-08-20  VMSA-2009-0010
Initial security advisory after release of Workstation 6.5.3,
Player 2.5.3, and ACE 2.5.3 on 2009-08-20.


[TZO-05-2009] Clamav 0.94 and below - Evasion /bypass

23/05/2009 : Asked clamav if the release was made and if credit was 
             given

23/05/2009 : Clamav responds that the release was made, and that the
             credit was given in the changelog. (Tzo note: A post will 
             be probably be made at http://www.clamav.net/category/security/
                                 
02/01/2009 : Release of this limited detail advisory

Final comments :

Immunity Debugger 1.5

gather more information from the remote process, such as Threads,
findRetValue. This release also includes some important fixes such as
correct Memory Page protection flags, which are also available via the
Python API.

Check the Changelog below for the details of this exciting release.

As usual, you can discuss your scripts, request new features or just hang
out at our forum: http://forum.immunityinc.com.  We would like to thank
Teddy Roggers from tuts4you for maintaining a list of Immunity Debugger
ported plug-ins that can be found at

VMSA-2008-0009 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion, VMware Server, VMware VIX API, VMware ESX, VMware ESXi resolve critical security issues

   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0888
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0062
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0063
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0948

6. Change log:

2008-06-04  VMSA-2008-0009    Initial release

- -------------------------------------------------------------------
7. Contact:

[ MDVSA-2008:224-1 ] kernel

 
 Additionaly, a problem with TCP options ordering, which could manifest
 as connection problems with many websites (bug #43372), was solved, a
 number of fixes for Intel HDA were added, another number of fixes for
 issues on Asus EEE PC, Panasonic Let's Note, Acer One, Dell XPS, and
 others, were also added. Check package changelog for more information.
 
 
 
 To update your kernel, please follow the directions located at:
 

VMSA-2010-0007 VMware hosted products, vCenter Server and ESX patches resolve multiple security issues

   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1139
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1140
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1142
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1141

6. Change log
2010-04-09  VMSA-2010-0007
Initial security advisory after release of Workstation 6.5.4 and Fusion
2.0.7 on 2010-04-08.

- ------------------------------------------------------------------------

[ MDVSA-2008:167 ] kernel

 re-ordered access to the descriptor table. (CVE-2008-1669)
 
 Additionaly, a number of fixes has been included for the rtc driver,
 Arima W651DI audio chipset, unionfs, as well as Tomoyolinux has
 been updated to 1.6.3, UDF 2.50 support was added, and a few things
 more. Check the package changelog for more details.
 
 To update your kernel, please follow the directions located at:
 
   http://www.mandriva.com/en/security/kernelupdate
 _______________________________________________________________________

CA20090126-01: CA Anti-Virus Engine Detection Evasion Multiple Vulnerabilities [Updated]

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0042
OSVDB References: OSVDB ID 53604
http://osvdb.org/53604


Changelog for this advisory:
v1.0 - Initial Release
v1.1 - Updated list of affected products, and added solutions.
v1.2 - Added CA ARCserve patch solution.
v1.3 - Updated CA ARCserve patch solution.


CA ARCserve Backup for Laptops and Desktops Server and CA Desktop Management Suite Multiple Vulnerabilities

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1328
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1329
OSVDB References: Pending
http://osvdb.org/

Changelog for this advisory:
v1.0 - Initial Release

Customers who require additional information should contact CA
Technical Support at http://support.ca.com.


VMSA-2008-0013 Updated ESX packages for OpenSSL, net-snmp, perl

   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2292
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0960
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1927

- ------------------------------------------------------------------------
6. Change log

2008-08-12  VMSA-2008-0013    
Initial release following release of ESX 3.0.3.

- ------------------------------------------------------------------------

VMSA-2008-00011 Updated ESX service console packages for Samba and vmnix

  http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1669
  http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4814
  http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1105

- -------------------------------------------------------------------
6. Change log:

2008-07-28  VMSA-2008-0011    Initial release

- ---------------------------------------------------------------------
7. Contact:

[CAID 35673, 35674, 35675, 35676, 35677]: CA ARCserve Backup for Laptops and Desktops Multiple Server Vulnerabilities

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5005
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5006
OSVDB References: Pending
http://osvdb.org/

Changelog for this advisory:
v1.0 - Initial Release

Customers who require additional information should contact CA
Technical Support at http://supportconnect.ca.com.


Re: WinAppDbg 1.4 is out!

>  * several improvements to the Window instrumentation classes
>  * more code examples
>  * more Win32 API wrappers
>  * lots of miscellaneous improvements, more documentation and bugfixes as usual!
>
> Entire changelog for all versions (slow!):
>
>  http://p.sf.net/winappdbg/changelog
>
>
> Where can I find WinAppDbg?

[ MDVSA-2010:247 ] kernel

 2.6.31.14. A timeout bug in bnx2 has been fixed. Muting and unmuting
 on VT1812/VT2002P now should work correctly. A fix for ACL decoding
 on NFS was added. Rebooting on Dell Precision WorkStation T7400 was
 corrected. Read balancing with RAID0 and RAID1 on drives larger then
 2TB was also fixed. A more detailed description is available in the
 package changelog and related tickets.
 
 Thanks to Thomas Backlund and Herton Ronaldo Krzesinski for
 contributions in this update.
 
 To update your kernel, please follow the directions located at:

VMSA-2010-0018 VMware hosted products and ESX patches resolve multiple security issues

   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4297
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4294

- ------------------------------------------------------------------------

6. Change log

2010-12-02  VMSA-2010-0018
Initial security advisory after release of Workstation 6.5.5,
Player 2.5.5, Fusion 2.0.8 and Fusion 3.1.2 on 2010-12-02, ESX patches
and Workstation 7.1.2 and 7.1.3 were released previously.

Editran editcp V4.1 R7 - Remote buffer overflow

  0x10008260 (lsConnectionCached+0x1c) 4186004c         beq   cr1,0x100082ac (lsConnectionCached+0x68)
  0x10008264 (lsConnectionCached+0x20) 813f0040         lwz   r9,0x40(r31)
  0x10008268 (lsConnectionCached+0x24) 3960ffff          li   r11,-1


.: [ CHANGELOG ] :.

  * 22/Jun/2010:   - Vulnerability discovered.
  * 22/Jun/2010:   - Vendor contacted.
  * 23/Jun/2010:   - Vendor response providing hotfix.
  * 05/Jul/2010:   - Public disclosure.

VMSA-2012-0006 VMware ESXi and ESX address several security issues

   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4348
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4862

 -----------------------------------------------------------------------

6. Change log

   2012-03-29 VMSA-2012-0006
   Initial security advisory in conjunction with the release of patches
   for ESX 4.0 on 2012-03-29.


Cisco Unified Operations Manager Multiple Vulnerabilities - SOS-11-006

http://target:1741/cwhp/auditLog.do?file=..\..\..\..\..\..\..\Program 
Files\CSCOpx\lib\classpath\com\cisco\nm\cmf\dbservice2\DBServer.proper
ties
Note: When reading large files such as this file, ensure the row
limit is adjusted to 500 for example.
DB password change log:
http://target:1741/cwhp/auditLog.do?file=..\..\..\..\..\..\..\Program 
Files\CSCOpx\log\dbpwdChange.log
Solution.
Upgrade to CuOM 8.6. 
Refer to Cisco Bug IDs: CSCtn61716, CSCto12704, CSCto12712 and

PHP Security Framework: Vuln and Security Bypass

    Advisory:   http://acid-root.new.fr/?0:16
      Author:   DarkFig < gmdarkfig (at) gmail (dot) com >

 Released on:   2007/12/16
   Changelog:   2007/12/16

     Summary:   [HT] Remote File Inclusion
                [MT] SQL Injection
                [MT] SQL Injection Protection Bypass
                [__] Conclusion

WinAppDbg 1.3 is out!

 * Win32 API wrappers were refactored and improved. Many new definitions and
   API calls were added, up to Windows 7.
 * Many bugfixes as usual... :) also several improvements to make the code more
   robust.

Here's the full changelog:

   http://sourceforge.net/apps/trac/winappdbg/log/trunk?verbose=on&format=changelog&stop_rev=237&limit=300&mode=stop_on_copy



VMSA-2012-0001 VMware ESXi and ESX updates to third party library and ESX Service Console

   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2089
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1521

 ----------------------------------------------------------------------

6. Change log

   2012-01-30 VMSA-2012-0001
   Initial security advisory in conjunction with the release of patches
   for ESX 4.1 and ESXi 4.1 on 2012-01-30.


VMSA-2010-0011 VMware Studio 2.1 addresses security vulnerabilities in virtual appliances created with Studio 2.0.

   CVE numbers
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2427
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2667

- ------------------------------------------------------------------------
6. Change log

2010-07-13  VMSA-2010-0011
Initial security advisory after release of Studio 2.1 on 2010-07-13.

- -----------------------------------------------------------------------

[CAID 35724, 35725, 35726]: CA BrightStor ARCserve Backup Multiple Vulnerabilities

CVE-2007-5332 - mediasvr and caloggerd memory corruption
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5332
OSVDB References: Pending
http://osvdb.org/

Changelog for this advisory:
v1.0 - Initial Release

Customers who require additional information should contact CA
Technical Support at http://supportconnect.ca.com.


VMSA-2012-0002 VMware vCenter Chargeback Manager Information Leak and Denial of Service

   CVE numbers
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1472

 ------------------------------------------------------------------------
6. Change log

   2012-03-08 VMSA-2012-0002 Initial security advisory in conjunction
   with the release of CBM 2.0.1 on 2012-03-08.

 -----------------------------------------------------------------------

[ MDVSA-2009:032 ] kernel

 systems with HDA sound needing MSI support were added to the quirks
 list to be autodetected, STAC92HD71Bx and STAC92HD75Bx based HDA
 support was enhanced and fixed, support for HDA sound on Acer Aspire
 8930 was added, Dell Inspiron Mini 9 HDA sound support was added, CIFS
 filesystem should now work with Kerberos, and a few more things. Check
 the package changelog for details.
 
 To update your kernel, please follow the directions located at:
 
   http://www.mandriva.com/en/security/kernelupdate
 _______________________________________________________________________

Insomnia : ISVA-110822.1 - Pidgin IM Insecure URL Handling Remote Code Execution

 Solution
_______________

Upgrade to Pidgin 2.10.0 from http://www.pidgin.im/
The Pidgin changelog can be found http://developer.pidgin.im/wiki/ChangeLog

_______________

 Legals
_______________

VMSA-2011-0008 VMware vCenter Server and vSphere Client security vulnerabilities

   VMSA-2011-0003
   http://www.vmware.com/security/advisories/VMSA-2011-0003.html

- ------------------------------------------------------------------------
6. Change log

2011-05-05  VMSA-2011-0008
Initial security advisory in conjunction with the release of vCenter
Server 4.0 Update 3 and VirtualCenter 2.5 Update 6a on 2011-05-05.


VMSA-2012-0007 VMware hosted products and ESXi/ESX patches address privilege escalation

   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1518

 -----------------------------------------------------------------------

6. Change log

   2012-04-12 VMSA-2012-0007
   Initial security advisory in conjunction with the release of
   Fusion 4.1.2 on 2012-04-12.


Secunia Research: Winamp VP6 Content Parsing Buffer Overflow Vulnerability

             back from the development team.
12/10/2010 - Status update requested. Disclosure date now set to 20th 
             October 2010.
19/10/2010 - Vendor provides status update.
27/10/2010 - Secunia becomes aware that a beta was released, which 
             includes a changelog mentioning the security fix.
27/10/2010 - Public disclosure.

====================================================================== 
7) Credits 


[CAID 35724, 35725, 35726]: CA BrightStor ARCserve Backup Multiple Vulnerabilities

CVE-2007-5332 - mediasvr and caloggerd memory corruption
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5332
OSVDB References: Pending
http://osvdb.org/

Changelog for this advisory:
v1.0 - Initial Release
v1.1 - Provided updated patch information, modified file 
       information in "How to determine if you are affected" 
       section.


<<Previous Next>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!